Debian
debian
10,146 CVEs • 112 products
Products (112)
Click to collapseToggle
Products (112)
Click to collapse
CVEs (10,146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jan 4, 2021 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path dis...Show more |
2Debian Ffmpeg2Debian Linux FfmpegJun 17, 2026 Jan 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations. |
2Debian Gssproxy Project2Debian Linux GssproxyJun 17, 2026 Dec 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gssproxy (aka gss-proxy) before 0.8.3 does not unlock cond_mutex before pthread exit in gp_worker_main() in gp_workers.c. NOTE: An upstream comment states "We are already on a shutdown path when running the code in quest...Show more |
2Debian Linbit2Csync2 Debian LinuxJun 17, 2026 Dec 30, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in LINBIT csync2 through 2.0. It does not correctly check for the return value GNUTLS_E_WARNING_ALERT_RECEIVED of the gnutls_handshake() function. It neglects to call this function again, as requi...Show more |
2Debian Nokogiri2Debian Linux NokogiriJun 17, 2026 Dec 30, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are...Show more |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Dec 28, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishand...Show more |
3Debian FedoraprojectWavpack3Debian Linux FedoraWavpackJun 17, 2026 Dec 28, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2,...Show more |
4Debian FasterxmlNetapp+1 more40Agile Plm Application Testing SuiteAutovue+37 moreJun 17, 2026 Dec 27, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org....Show more |
2Debian Td Agent Builder Project2Debian Linux Td Agent BuilderJun 17, 2026 Dec 24, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM. |
2Debian Kovidgoyal2Debian Linux KittyJun 17, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message. |
2Debian Postsrsd Project2Debian Linux PostsrsdJun 17, 2026 Dec 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 srs2.c in PostSRSd before 1.10 allows remote attackers to cause a denial of service (CPU consumption) via a long timestamp tag in an SRS address. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are h...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibi...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights,...Show more |
4Debian FasterxmlNetapp+1 more26Agile Plm Application Testing SuiteAutovue For Agile Product Lifecycle Management+23 moreJun 17, 2026 Dec 17, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource. |
4Debian FasterxmlNetapp+1 more25Agile Plm Application Testing SuiteAutovue For Agile Product Lifecycle Management+22 moreJun 17, 2026 Dec 17, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource. |
3Debian OracleP11 Kit Project3Communications Cloud Native Core Policy Debian LinuxP11 KitJun 17, 2026 Dec 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity suppli...Show more |
2Debian P11 Kit Project2Debian Linux P11 KitJun 17, 2026 Dec 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing b...Show more |
4Apache DebianFedoraproject+1 more4Debian Linux FedoraStruts+1 moreJun 17, 2026 Dec 16, 2020 N/A· v4 6.8 MEDIUM· v3 6.4 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remo...Show more |